MaaS Appeal: An Infostealer Rises From The Ashes
ID: 55d2646f-c3c6-5b3c-a8b3-5245d7baa33b
STIX ID: report--55d2646f-c3c6-5b3c-a8b3-5245d7baa33b
Feed Name: Elastic Security Labs
NOVABLIGHT is a modular NodeJS/Electron infostealer offered as Malware-as-a-Service through Telegram and Discord; it supports credential and wallet theft (browser and Electron app injections), clipboard clipping, system enumeration (screenshots, webcam, Wi‑Fi passwords), anti-analysis checks, attempts to disable Defender/Task Manager and to sabotage recovery, and exfiltrates data to a hosted web panel, Discord webhooks, or Telegram proxies. The report includes infrastructure and IOCs (domains and hashes), build/distribution details, heavy obfuscation techniques, and evidence linking the actor to an established MaaS community.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
